Simon Willison’s Weblog

Entries tagged google, http, rfc, csrf

Filters: Type: entry × google × http × rfc × csrf ×

Fighting RFCs with RFCs

Google’s recently released Web Accelerator apparently has some scary side-effects. It’s been spotted pre-loading links in password-protected applications, which can amount to clicking on every “delete this” link — bypassing even the JavaScript prompt you carefully added to give people the chance to think twice.

[... 353 words]